NIST CSF tables
Summarize
Summary of NIST CSF tables
The NIST CSF tables in ServiceNow's Zurich release provide structured data management for cybersecurity activities aligned with the NIST Cybersecurity Framework (CSF). These tables facilitate tracking, analysis, and reporting across various cybersecurity elements such as activities, gaps, non-compliant controls, risks, issues, action plans, and failed indicators. They are designed to support integration with ServiceNow GRC applications and use-case content packs.
Show less
Key Tables and Their Purposes
- Target [sngrctarget]: Serves as a core shared entity to represent cybersecurity targets across GRC applications. It tracks attributes specific to use-case content packs and ensures unique association with entities.
- NIST CSF Activity [snirmnistcsfnistcsfactivity]: Tracks cybersecurity activities relevant to targets to perform gap analysis, identifying gaps, non-compliant controls, risks, issues, failed indicators, and corresponding action plans.
- Gaps [snirmnistcsfm2mpolicystatenistcsfact]: Tracks unimplemented control objectives as gaps, enabling detailed reporting and drill-down analysis. Functions as a many-to-many table associating gaps with targets.
- Non-compliant Control [snirmnistcsfm2mcxontrolsnistcsfact]: Tracks controls identified as non-compliant under cybersecurity control objectives. Supports reporting and drill-down by associating non-compliant controls with targets.
- Risk [snirmnistcsfm2mrisksnistcsfactivities]: Records risks linked to implemented controls within cybersecurity objectives. Enables risk management reporting and drill-down by associating risks with targets.
- Issue [snirmnistcsfm2missuesnistcsfact]: Tracks issues related to controls and associated risks, supporting detailed reporting and drill-down, and linking issues to targets.
- Action Plan [snirmnistcsfm2mremediationnistcsfact]: Captures action plans or remediation tasks identified for issues, facilitating management and reporting by associating these plans with targets.
- Failed Indicators [snirmnistcsfm2mindicatorsnistcsfact]: Tracks failed indicators related to targets, controls, or risks, aiding in performance monitoring and reporting through associations with targets.
- Related Control Objectives [sncompliancem2mpolicystmtpolicystmt]: Manages associations between control objectives at the same hierarchical level, extending beyond parent-child relationships to enhance control objective mapping.
Practical Benefits for ServiceNow Customers
These NIST CSF tables enable customers to effectively manage cybersecurity compliance by:
- Centralizing cybersecurity data aligned to the NIST CSF framework for consistency across GRC solutions.
- Facilitating comprehensive gap analysis and risk assessment to prioritize remediation efforts.
- Supporting detailed reporting and drill-down capabilities for controls, risks, issues, and indicators.
- Enhancing traceability and management of remediation action plans tied directly to cybersecurity targets.
- Improving control objective relationships to better reflect organizational cybersecurity structures.
Overall, these tables support a structured and integrated approach to cybersecurity governance, risk, and compliance management within the ServiceNow platform.
A few tables are impacted by the NIST CSF guidance.
| Table | Purpose |
|---|---|
| Target [sn_grc_target] | Target is a core table of design to be shared component among the ServiceNow GRC application and GRC use-case content packs.Target is like entity in its purpose, but is used to track any attributes specific to use-case content packs. No two target records can reference the same entity at any time. |
| NIST CSF Activity [sn_irm_nist_csf_nist_csf_activity] | NIST CSF Activity table is used to track cybersecurity activity relevant for a target. The activity also helps in performing gap analysis that identifies the gaps, non-complaint controls, risks, issues, failed indicators and action plans for a cybersecurity activity. |
| Gaps [sn_irm_nist_csf_m2m_policy_state_nist_csf_act] | Gaps table in NIST CSF is used to track control objectives that aren’t yet implemented as gaps. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Gaps to Targets. |
| Non-compliant Control [sn_irm_nist_csf_m2m_cxontrols_nist_csf_act] | Non-compliant Control table in NIST CSF is used to track controls that are identified as non-compliant. Only cybersecurity control objectives as defined by the framework core which are implemented as controls and non-compliant are tracked. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Non-compliant Controls to Targets. |
| Risk [sn_irm_nist_csf_m2m_risks_nist_csf_activities] | Risk table in NIST CSF is used to track risks that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Risks to Targets. |
| Issue [sn_irm_nist_csf_m2m_issues_nist_csf_act] | Issue table in NIST CSF is used to track issues that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. Issues of risks associated with these controls are also included in the metric. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Issues to Targets. |
| Action Plan [sn_irm_nist_csf_m2m_remediation_nist_csf_act] | Action Plan table in NIST CSF is used to track the action plans that are identified for the issues. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Action Plans (remediation tasks) to Targets. |
| Failed Indicators [sn_irm_nist_csf_m2m_indicators_nist_csf_act] | Failed indicators table in NIST CSF is used to track the failed indicators of the target and the control or risk. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Failed Indicators to Targets. |
| Related Control Objectives [sn_compliance_m2m_policy_stmt_policy_stmt] | Related Control Objectives table in NIST CSF is used to track the associations between control objectives. In base implementation, parent and child control objectives are supported, but this table introduces a concept to relate the control objectives at the same level. |